2 ms·
> Such access should be restricted (requiring approval) and logged, of course, but it's difficult to eliminate entirely at scale. It’s not clear how you could
by bdhess 8y ago
> Such access should be restricted (requiring approval) and logged, of course, but it's difficult to eliminate entirely at scale.
It’s not clear how you could practically enforce this requirement if devs just have the raw key on their workstations.
- hanniabu 8y agoWould be nice to use a multi-sig so the dev would need their key which they always have access to plus a key from an approver.